still
Privacy

We profile places. Not people.

"The question isn't what we know about you. It's what you know about the place."

the map knows terrain, not you — places, never people

Most personalization works by learning about you and selling what it learns. Ours doesn't.

The standard model for a "personalized" digital product goes like this: you use the product, the product observes what you do, it builds a profile of who you are, it shares or sells that profile to people who want to reach you, and it uses the profile to keep you engaged. Sometimes this is useful. Often it is extractive. Always it is happening without your full awareness of what's being built about you.

We made a different architectural choice — not as a feature, but as a foundation.

Still's intelligence lives in its knowledge of places, not in its knowledge of you. Every place in our system is a permanent record — a UUID, a geographic location, and a collection of observations drawn from public data sources, each labeled with where it came from, when it was retrieved, and how confident we are in it. The observations are about the place. They always were. They always will be.

Your criteria — the weights you set, the dimensions you prioritize, the dealbreakers you specify — are used to score places at the moment you ask. They are not stored in a profile. They are not used to infer things about you. They are not shared. They are not sold. When you close the session, they are yours and you can export them. They are not ours.

This isn't a privacy policy. It's a description of how the thing actually works. The policy is below, for the people who want the policy. But we wanted to explain the architecture first, because the architecture is the commitment.

Nothing hidden. All decisions deliberate.

"Nothing hidden, all decisions deliberate" is a principle we adopted early in building the Habitus platform — the engine that powers still. It started with a specific technical realization: we had been silently transforming uploaded photos in a way users hadn't consented to and couldn't see. We removed the transformation. We wrote the principle down. It governs everything we build now.

Applied to privacy, it means: anything we store, we store deliberately, and we tell you what it is and why.

What we store about places

A permanent identifier (UUID) for each place, paired with a nullable Mapbox location reference. Observations drawn from public data: noise levels, air quality readings, dark-sky data, green-space access, climate risk scores, and other environmental metrics. Each observation carries its source, its retrieval date, and our confidence in it. Observations are append-only — we don't overwrite history. When new data arrives, we record it as a new observation, not a replacement.

What we store about your session

Your criteria weights, if you choose to save them. Your saved areas of interest (the geographic polygons you draw to watch for new listings). Your alert preferences.

What we don't store

A profile of who you are. Inferences about your identity, your health, your demographics, or your circumstances drawn from your usage. Your browsing behavior beyond what's necessary to make the product work. Anything we could sell.

When you delete your data

We delete it. We don't retain derived inferences. We don't archive it under a different name. Gone means gone.

We don't take what isn't ours.

When we surface property listings as part of the alert system, we use licensed data from providers who have the right to share it. We don't scrape Zillow, Redfin, or any other platform whose data we haven't licensed. If you forward a listing email to our parser, you're sharing something you received — that's yours to share. We process it to extract an address, score it against your criteria, and then discard the message. We don't store the email content.

We don't have advertising partners. We don't sell access to your data or your attention. Still is not free because it's funded by people who want to reach you. If we build a paid tier, we'll say so plainly. The information you provide to find a place to live is not a revenue stream for anyone other than you.

The data we use has history in it.

Some of the public data we rely on was produced by agencies and systems that have not always been neutral. Flood-zone maps have historically undercounted risk in some areas and overcounted it in others, along lines that correlate with race and income. Air-quality monitoring is sparser in lower-income communities, which means the absence of a nearby sensor is not the same as clean air — it may just be that no one looked. School ratings carry well-documented bias; we use them cautiously and transparently.

We flag these issues in the score where they're material. We don't hide the gap by presenting confident numbers where the data doesn't warrant confidence. And we're working on the coverage problem directly: part of what we're building is the ability for communities to contribute hyperlocal measurements that fill the gaps the official data leaves.

Privacy summary

Draft — pending legal sign-off. This is a plain-language summary, not a finalized legal policy. It will be reviewed before public launch.

What we collect: criteria weights you choose to save, geographic areas of interest you create, and your alert preferences. Environmental observations are about places, not about you.

What we don't do: sell your data, build a behavioral profile, share your information with advertisers, retain deleted data.

Third-party data: we use licensed APIs for property listings and public APIs for environmental data. We do not scrape platforms that prohibit it.

Cookies: we use session cookies for functionality. We do not use tracking cookies or third-party ad cookies.

Questions: [contact — pending]